All CVEs
Vulnerability intelligence

CVE-2026-26980

CWE-89

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

CVSS Score
9.4
Critical
EPSS — Exploit Probability
70%
Riskier than 99% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

6 articles across 5 outlets · first covered May 25, 2026 · latest May 31, 2026

Associated threat actors

Coverage timeline